CounterCraft is designed to integrate easily with all your team’s top software solutions. CounterCraft Integrations is the first in our new video series showing you how our security technology plays well with software you already use and, in the process, makes your life a whole lot easier. Watch this video to find out more.
Splunk is an industry-leading SIEM platform that provides real-time analysis of security alerts generated by applications and network hardware. Splunk is used for log management, alerting, and correlation of events to detect patterns or anomalies that can indicate threat actor behavior.
When integrated with CounterCraft, Splunk receives event data from the deception environment and displays it within Splunk’s interface. You can integrate the event data from CounterCraft into the wider security database of information and events collected from other systems, enriching the dataset with CounterCraft’s real time, actionable threat intel and enhancing your SIEM’s capacity.
A CounterCraft / Splunk integration will help you ingest the valuable first-party threat intelligence from the CounterCraft deception environment into your existing security event management infrastructure.
Now you can:
- take advantage of deception data immediately and fast track network-wide breach detection
- access threat data from a deception deployment without learning a new tool
- convert the deception threat intel into another CTI feed without modifying your threat handling process
To integrate Splunk and CounterCraft, it’s simple. Just
- Open the Cyber Deception Platform
- Under “Integrations”, enable the Splunk Server as a destination for event data
- Set up a rule to say which events get sent to the Splunk server. You can choose to send everything or only send specific event data.
- Click ‘Save’ and you’re done. That’s it!
Download the CounterCraft App in the Splunk store to make it even easier to visualise the feed inside Splunk.
Subscribe to our YouTube channel for more of the latest news on CounterCraft integrations!